CVE-2026-78037

HIGH8.8Pubblicata il 28 agosto 2026

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

Punteggio CVSS8.8 / 10CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-78

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE